Docs · Reference
Data boundaries reference
See where EmailOS private work, approved Team Knowledge, and bounded account or action evidence stay and what each path can share.
On this page
On this page
A plain-language map of private work, approved sharing, and bounded evidence
EmailOS keeps private inbox work on its owning Mac. Approved Team Knowledge can move between approved Macs. The portal receives only bounded account and evidence metadata.
Keep private work on its Mac
EmailOS prepares eligible email work locally. Email, drafts, and your private Knowledge stay on the owning Mac during that work.
The portal does not receive private message bodies, draft text, private Knowledge, prompts, retrieved passages, or provider results. This boundary does not mean every workflow is offline. An approved connection or content-free evidence path is a separate, named exception.
Move approved Team Knowledge deliberately
Team Knowledge is different from private inbox work. A document or fact may move between approved Macs only after the source owner, destination, permission, purpose, and current policy allow it.
The path is intentionally narrow:
Approved source → permission and purpose checks → approved Mac → cited Team Knowledge
An approved source does not make every private record shareable. If scope, purpose, or approval is missing, the Mac stops and asks for a clearer decision.
Send bounded account evidence
Some portal records describe an account or device without carrying its content. They can include licence or billing status, device and connection state, revocation or policy timing, and content-free action evidence.
-
EmailOS private work: Owning Mac; no private-content payload; excludes email, drafts, prompts, and private Knowledge.
-
Approved Team Knowledge: Approved Macs chosen by the owner; approved facts with scope and citations; excludes unapproved inboxes and unrelated private records.
-
Account and licence controls: Portal and authorised device controls; bounded status, purpose, timing, and device metadata; excludes credentials, provider payloads, queries, and results.
-
Action evidence: Owning Mac with permitted summary metadata; records the action and unused data class; excludes message bodies, retrieved passages, and diagnostic contents.
Check the boundary before sharing
Before you approve a source, name its owner, purpose, audience, and time limit. Check the visible permission and current device state. Share only the smallest approved scope.
For a deeper explanation of evidence records, read what a Lithi Receipt can show.
Ask your AI how Lithi can help
Copy a page-aware prompt into the AI you already use.